Sponsored
Software

AI Can Reveal Where Your Travel Photo Was Taken Without GPS

McAfee research on 21,236 images shows how visual clues alone can expose a travel location and enable more convincing scams

Τουρίστας φωτογραφίζει ταξιδιωτικό προορισμό ενώ σύστημα AI αναλύει στοιχεία της εικόνας για γεωεντοπισμό
AI vision models can infer where a travel photo was taken by analyzing visual clues even when GPS and EXIF location data are absent.

Summary

  • McAfee tested two AI vision models on 21,236 travel photos without GPS, EXIF data or information from filenames
  • Qwen3 VL 30B correctly identified the city and country in 91% of the specific dataset, while Gemma3 27B achieved 87%
  • The 91% figure is not a universal success rate for every image or every AI model
  • Architecture, signs, roads, vegetation and other visual clues can reveal a location
  • The information could make phishing and travel scams substantially more convincing
  • Delayed posting and tighter social media visibility can reduce exposure
Contents
  1. What exactly McAfee tested
  2. A photo can reveal its location without GPS
  3. From one photo to a much more convincing phishing message
  4. The 91% figure needs context
  5. The issue goes beyond financial scams
  6. What travelers and photographers can do
  7. What we think
  8. Frequently asked questions

A simple holiday photo can now reveal the city where it was taken even without GPS, EXIF data or a geotag, creating a new and potentially powerful source of information for targeted online scams.

McAfee Labs research involving 21,236 travel images found that Qwen3 VL 30B correctly identified the city and country in 91% of tests, while Gemma3 27B achieved 87%, relying exclusively on the visual information in each photo.

The significance of the finding is not that every photograph can be located with that level of accuracy, but that image geolocation has become sufficiently capable and accessible for someone to turn a publicly shared travel photo into material for far more convincing phishing without ever accessing the image’s metadata. McAfee itself stresses that the 91% result should not be interpreted as a universal accuracy figure for every photo or every AI model.

What exactly McAfee tested

McAfee Labs built an automated testing pipeline using 21,236 publicly available travel images. Each photograph was submitted to the models using a standardized request to determine its location from visual content alone. GPS data, EXIF metadata and information contained in filenames were not used.

The two models were Gemma3 27B and Qwen3 VL 30B, both running locally on the researchers’ computers. A result was counted as correct when both the city and country were identified. Under that definition, Gemma3 27B achieved 87% accuracy and Qwen3 VL 30B reached 91%.

McAfee also ran a separate controlled test involving 102 personal images supplied by employees that had never previously been posted publicly. Accuracy was lower than in the large dataset, but the models could still frequently identify at least the country, which may be sufficient to make a deceptive message more believable.

A photo can reveal its location without GPS

For years, one of the standard privacy recommendations for photographs has been to remove geotags and GPS information from EXIF metadata. The research suggests that this remains useful but is no longer sufficient on its own.

Modern Vision-Language Models can combine signs, architecture, road markings, vegetation, landscapes, storefronts, transportation and other less obvious details in a scene to estimate where an image was captured. Photos containing famous landmarks, distinctive skylines or visible signage were, unsurprisingly, among the easiest cases.

More importantly, a world-famous landmark is not always required. In examples involving real photographs supplied by McAfee employees, a model recognized Hastings-on-Hudson from a sunset image, while another photo showing primarily tulips was identified as the Keukenhof gardens in the Netherlands.

Independent academic research points in the same general direction. Modern Vision-Language Models demonstrate substantial image-geolocation capability using visual content alone, with particularly important privacy implications for the kind of images people post to social networks. A study evaluating 25 models found significantly stronger performance on a dataset designed to resemble social-media images than on generic street-level imagery.

From one photo to a much more convincing phishing message

The risk is not limited to someone guessing where the photographer has been. The information can become one component in a broader social-engineering scenario.

If a publicly shared image indicates that someone is or was recently in Portugal, for example, a fake banking alert about a suspicious transaction in Portugal immediately becomes more plausible. The same approach could be applied to fake communications claiming to come from a hotel, airline or booking service, or to messages sent to relatives while impersonating the traveler.

McAfee describes a potential workflow in which a scammer gathers publicly available images, analyzes them using an AI vision model, infers likely location and travel context, and then creates a personalized message around that information. Significant parts of this process could be automated.

That does not mean the research proved that every current travel scam is already using AI geolocation. It does demonstrate, however, that the technical capability already exists and that access to suitable models no longer requires specialist infrastructure.

The 91% figure needs context

The 91% number is striking, but it needs to be interpreted carefully.

It represents the performance of one specific model, Qwen3 VL 30B, on a particular collection of 21,236 travel images under McAfee’s testing methodology. McAfee explicitly notes that performance varies according to image type, geographic region and the amount of location-specific information visible in the frame.

Independent research supports that qualification. A large evaluation involving 25 Vision-Language Models found substantial variation across datasets and models, with systems generally struggling more on generic street-level imagery.

The appropriate conclusion, therefore, is not that “AI knows where 91% of all photos were taken.” It is that, under favorable conditions, geolocation from a single image can now be extremely effective without any geotag being present.

The issue goes beyond financial scams

Inferring a person’s location from an image has broader implications for privacy. Research from Privacy International and academic collaborators highlights risks including surveillance, identification or re-identification, doxxing, profiling and other potential forms of misuse.

For photographers, creators and travelers, this changes a long-standing assumption: a photograph without GPS information is not necessarily a photograph without location information. The visual content itself can act as an indirect geographic identifier.

The timing of a post is also important. A publicly shared photograph uploaded while someone is still traveling may reveal not only where they went but where they may be at that particular moment.

What travelers and photographers can do

One of the simplest changes is to delay posting. McAfee recommends publishing identifiable travel photographs after returning home where possible, or at least waiting before sharing location-revealing content so that an inferred location is not a real-time signal.

Restricting the visibility of posts can also help, particularly for personal accounts. Removing GPS and EXIF information remains worthwhile as well, but it should not be considered complete protection against visual geolocation.

If an SMS, email or other communication correctly references the city or country where the recipient is traveling, that detail can no longer be treated as proof that the sender really is a bank, hotel or airline. The safer approach is to verify the communication through a separate official channel rather than following a link contained in the message.

What we think

The most important part of this research is not the headline-grabbing 91% figure, but the change it illustrates in the basic assumptions surrounding photo privacy. Removing a geotag no longer necessarily removes the location: the image itself may contain enough information for a modern AI model to make a reliable estimate.

For most people, the answer is not to stop sharing photographs. Greater care is needed, however, over what appears in the frame, who can see the post and, most importantly, whether the image is being published in real time. At the same time, a message that correctly knows where someone is traveling should now be treated as potentially deceptive rather than automatically authentic.

Frequently asked questions

Can AI really find where a photo was taken without GPS?

Yes. Modern Vision-Language Models can use visual information including architecture, signs, landscapes, vegetation and other characteristics to estimate a location. Accuracy, however, varies significantly according to the photograph and the model.

Does the 91% figure mean almost every photo can be located?

No. The 91% result applies to Qwen3 VL 30B on the specific dataset of 21,236 travel photographs used in McAfee’s test. The company explicitly states that it does not claim every photograph or AI model reaches comparable accuracy.

Is removing EXIF and GPS information enough?

Not completely. Removing that information prevents direct access to stored coordinates, but it does not remove geographic clues visible in the image itself.

Why is posting travel photos in real time more dangerous?

Because inferred location can reveal not only where someone traveled but where they may currently be, making deceptive messages more timely and believable.

What is the safest indication that a banking alert is genuine?

Correctly mentioning a city or country is not enough. A message should be verified independently through an official app, official service or another known communication channel rather than through a link in the suspicious message.

Comments

Leave a comment